Skip to main content
CybersecurityCloud Security

NIST Identifies Security Gaps in Multi-Cloud Environments

Neutral-colored room with multiple computer screens and servers, displays blurred or empty.

“By bounding the analysis, this IR aims to provide a structured problem statement and shared vocabulary that can inform future research, procurement, standards development, and solution design across government, industry, and academia,” the report stated.

Why NIST flagged multi‑cloud risks on August 21

On August 21, the National Institute of Standards and Technology (NIST) published a report warning that multi‑cloud environments — defined by the institute as using two or more cloud service providers (CSPs) — present distinctive cybersecurity and compliance challenges. NIST said a growing number of organizations are moving to multi‑cloud setups because they reduce reliance on a single provider and can maintain operations if a provider suffers an outage or cyber‑attack. But that operational resilience comes with tradeoffs: differing security models, tools, configurations and shared responsibility frameworks across CSPs make it difficult to maintain consistent defenses across an enterprise architecture.

Identity and Access Management challenges

NIST identified identity and access controls as a major source of friction in multi‑cloud environments. Security teams face difficulty ensuring that access control policies and authorization measures are implemented consistently across the native architectures of various CSPs. The report notes a concrete verification problem: customers may struggle to confirm whether multi‑factor authentication (MFA) or biometric verification have been employed by all their CSPs for the specific information systems that support their cloud services. Those verification challenges are amplified when CSPs rely on other vendors or third parties, because customers must also verify third‑party access control policies and implementations.

Vulnerability management hurdles across providers

Vulnerability management becomes more complex in multi‑cloud settings, NIST found. CSPs provide vulnerability reports on differing timeframes and in differing formats, which NIST says makes it effectively impossible to apply a uniform patch‑management approach across an enterprise. The institute also highlighted a technical constraint: customers may be unable to run independent vulnerability scans because they lack direct access to the CSPs’ information systems, limiting visibility and control over patching and remediation.

Incident response and disaster recovery complications

NIST warned that incident response and disaster recovery planning are particularly brittle when spread across multiple providers. Some CSPs may not send timely or comprehensive incident data to customers, and the reporting that does arrive can use varied formats and schemas that hinder rapid, coordinated response. In addition, CSPs may withhold the administrative access privileges customers would need to monitor their cloud services independently. Planning for disaster recovery is further hampered because CSPs frequently withhold contingency planning policies — citing concerns about privileged backend information and system security — and typically do not provide the results of contingency or disaster recovery plan tests.

Data protection and cross‑jurisdictional compliance

Data protection outcomes are uneven in multi‑cloud environments, NIST noted. Customers rely on CSPs to meet security, encryption and regulatory standards, but inconsistent implementations of data security measures such as encryption across providers can place organizations at risk of violating data protection laws in different jurisdictions. The report also flagged a practical compliance hurdle: organizations often face challenges obtaining information system security documentation from all providers involved in protecting their data, creating difficulties in proving compliance with laws such as the EU’s General Data Protection Regulation (GDPR).

What this means for federal agencies, industry partners, and researchers

  • Federal agencies: NIST has invited input from federal agencies, signaling that agencies will be expected to help shape standards, procurement requirements and potential guidance informed by the report’s structured problem statements.
  • Industry partners: Vendors and CSPs are named indirectly as necessary collaborators; NIST recommends that solutions emphasize centralized visibility, consistent policy enforcement, automation and standardization to address the 23 novel challenges it identified.
  • Researchers and the broader cybersecurity community: The institute is seeking contributions from researchers and other community members as part of a collaborative effort to develop technical and governance approaches to multi‑cloud security.

NIST enumerated 23 novel challenges spanning identity and access controls, vulnerability management, incident response and disaster recovery, and data protection. To address them, the institute urged robust governance frameworks, centralized visibility, consistent policy enforcement, and a strong emphasis on automation and standardization — and called for a collaborative response across government, industry and academia. The report’s public comment period is open until October 5, 2026, giving the community a concrete window to shape next steps.

Original story